aZURE ad dEVICE REGISTRATION

Sharing is caring!

&NewLine;<p>To protect the organisation&&num;8217&semi;s assets&comma; IT staff must first manage the device identities&period; IT staff can build on the device identity with tools like Microsoft Intune to ensure standards for security and compliance are met&period; Azure Active Directory &lpar;Azure AD&rpar; enables single sign-on to devices&comma; apps&comma; and services from anywhere through these devices&period; It&&num;8217&semi;s a win-win situation for both&excl;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Users get access to your organization&&num;8217&semi;s assets they need&period;<&sol;li><li>IT staff &sol; Security gets the controls they need to secure your organization&period;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Azure AD offers 3 Types of Device Registration &sol; Joining mechanisms&period; <&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Azure AD Registered devices<&sol;li><li>Azure AD joined devices<&sol;li><li>Hybrid Azure AD joined devices<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<blockquote class&equals;"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>The goal of <strong>Azure AD registered devices<&sol;strong> is to provide your users with support for the BYOD or mobile device scenarios&period; In these scenarios&comma; a user can access your organization’s Azure Active Directory controlled resources using a personal device&period; Azure AD registered devices are signed in to using a local account like a Microsoft account on a Windows 10 device&comma; but additionally have an Azure AD account attached for access to organizational resources&period;<&sol;p><&sol;blockquote>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-table"><table><thead><tr><th>Azure AD registered<&sol;th><th>Description<&sol;th><&sol;tr><&sol;thead><tbody><tr><td>Definition<&sol;td><td>Registered to Azure AD without requiring organizational account to sign in to the device<&sol;td><&sol;tr><tr><td>Primary audience<&sol;td><td>Applicable to Bring your own device &lpar;BYOD&rpar;&comma; and Mobile devices<&sol;td><&sol;tr><tr><td>Device ownership<&sol;td><td>User or Organization<&sol;td><&sol;tr><tr><td>Operating systems<&sol;td><td>Windows 10&comma; Windows 11&comma; iOS&comma; Android&comma; and macOS<&sol;td><&sol;tr><tr><td>Device sign in options<&sol;td><td>End-user local credentials&comma; Password&comma; Windows Hello&comma; PIN Biometrics<&sol;td><&sol;tr><tr><td>Device management<&sol;td><td>Mobile Device Management &lpar;example&colon; Microsoft Intune&rpar;<&sol;td><&sol;tr><tr><td>Key capabilities<&sol;td><td>SSO to cloud resources&comma; Conditional Access<&sol;td><&sol;tr><&sol;tbody><&sol;table><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<blockquote class&equals;"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p><strong>Azure AD join<&sol;strong> is intended for organizations that want to be cloud-first or cloud-only&period; Azure AD join enables access to both cloud and on-premises apps and resources&period; Azure AD joined devices are signed in to using an organizational Azure AD account&period; Access to resources in the organization can be further limited based on that Azure AD account and Conditional Access policies applied to the device identity&period;<&sol;p><&sol;blockquote>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-table"><table><thead><tr><th>Azure AD joined<&sol;th><th>Description<&sol;th><&sol;tr><&sol;thead><tbody><tr><td>Definition<&sol;td><td>Joined only to Azure AD requiring organizational account to sign in to the device<&sol;td><&sol;tr><tr><td>Primary audience<&sol;td><td>Suitable for both cloud-only and hybrid organizations<&sol;td><&sol;tr><tr><td>Device ownership<&sol;td><td>Organization<&sol;td><&sol;tr><tr><td>Operating systems<&sol;td><td>All Windows 10 &amp&semi; 11 devices except Windows 10 Home<&sol;td><&sol;tr><tr><td>Device management<&sol;td><td>Mobile Device Management &lpar;example&colon; Microsoft Intune&rpar;<&sol;td><&sol;tr><tr><td>Key capabilities<&sol;td><td>SSO to both cloud and on-premises resources&comma; Conditional Access&comma; Self-service Password Reset and Windows Hello PIN reset<&sol;td><&sol;tr><&sol;tbody><&sol;table><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<blockquote class&equals;"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>Organisations with an on-premises AD footprint can implement <strong>hybrid Azure AD joined devices&period;<&sol;strong> These devices are joined to your on-premises Active Directory and registered with your Azure Active Directory&period; This offers capability to use on-premise technology like GPO&comma; Windows auth and win 7 support etc&period; Device writeback helps you to keep a track of devices registered with Azure AD in AD&period; You will have a copy of the device objects in the container &&num;8220&semi;Registered Devices&&num;8221&semi;&period; Also&comma; Windows Hello For Business &lpar;WHFB&rpar; requires device writeback to in Hybrid- Federated scenarios&period;<&sol;p><&sol;blockquote>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-table"><table><thead><tr><th>Hybrid Azure AD joined<&sol;th><th>Description<&sol;th><&sol;tr><&sol;thead><tbody><tr><td>Definition<&sol;td><td>Joined to on-premises AD and Azure AD requiring organizational account to sign in to the device<&sol;td><&sol;tr><tr><td>Primary audience<&sol;td><td>Suitable for hybrid organizations with existing on-premises AD infrastructure<&sol;td><&sol;tr><tr><td>Device ownership<&sol;td><td>Organization<&sol;td><&sol;tr><tr><td>Operating systems<&sol;td><td>Windows 11&comma; 10&comma; 8&period;1 and 7&comma; along with Windows Server 2008&sol;R2&comma; 2012&sol;R2&comma; 2016 and 2019<&sol;td><&sol;tr><tr><td>Device sign in options<&sol;td><td>Password or Windows Hello for Business<&sol;td><&sol;tr><tr><td>Device management<&sol;td><td>Group Policy&comma; Configuration Manager standalone or co-management with Microsoft Intune<&sol;td><&sol;tr><tr><td>Key capabilities<&sol;td><td>SSO to both cloud and on-premises resources&comma; Conditional Access&comma; Self-service Password Reset and Windows Hello PIN reset<&sol;td><&sol;tr><&sol;tbody><&sol;table><&sol;figure>&NewLine;